corCTF 2022
45 challenges with 107 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not.
Full task list on CTFtimeCryptography9
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Also written up in: jontay999/CTF-writeups, banhcuon79/ctf-writeups, vnc1106/CTF-WriteUps, epicleet/write-ups, epicleet/write-ups
- rsa
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, john_pollard
Also written up in: jontay999/CTF-writeups, banhcuon79/ctf-writeups, banhcuon79/ctf-writeups, vnc1106/CTF-WriteUps, vnc1106/CTF-WriteUps
- oracle
- crypto
- okamoto-uchiyama
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Also written up in: banhcuon79/ctf-writeups, LeonGurin/My-CTF-Writeups, vnc1106/CTF-WriteUps
- crypto
- modular-arithmetic
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Also written up in: banhcuon79/ctf-writeups, vnc1106/CTF-WriteUps
- crypto
- lattice
- elliptic
- curves
Same technique in picoCTF: MSS_ADVANCE Revenge, Not TRUe, It's Not My Fault 2
Also written up in: jontay999/CTF-writeups, banhcuon79/ctf-writeups, vnc1106/CTF-WriteUps
- dlp
- lcg
- diffie-hellman
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Also written up in: banhcuon79/ctf-writeups, vnc1106/CTF-WriteUps
- lcg
- crypto
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Also written up in: banhcuon79/ctf-writeups, vnc1106/CTF-WriteUps
- crypto
- modular-arithmetic
- lcg
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Also written up in: banhcuon79/ctf-writeups, vnc1106/CTF-WriteUps
- coppersmith
- crypto
- ecc
- rsa
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, john_pollard
- crypto
- lfsr
Same technique in picoCTF: It's Not My Fault 2, StegoRSA, AES-ABC
Binary exploitation9
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Also written up in: rivit98/ctf-writeups, pivik271/ctf-writeups, ret2school/ctf, ret2school/ctf, ret2school.github.io
- largebin
- pwn
- tcache-poisoning
- heap-overflow
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: Skryptonyte/CTF-Writeups, rivit98/ctf-writeups, pivik271/ctf-writeups
- ret2libc
- pwn
- rust
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: mito753/Kernel-Exploit-Dojo, mito753/Kernel-Exploit-Dojo, mito753/Kernel-Exploit-Dojo
- pwn
- kernel
- cross-cache
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: rivit98/ctf-writeups, jt00000/ctf.writeup, ret2school.github.io
- zig
- pwn
- heap
Same technique in picoCTF: vr-school, sice_cream, zero_to_hero
Also written up in: smallkirby/pwn-writeups, smallkirby/pwn-writeups
- kernel
- pwn
- docker-escape
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Also written up in: strellic/my-ctf-challenges
Also written up in: strellic/my-ctf-challenges
Remote
1 official solutionAlso written up in: ret2school/ctf
Also written up in: ret2school/ctf
Uncategorised9
The upstream scoreboard did not say, so neither do we.
Also written up in: rivit98/ctf-writeups
Corchat
1 official solutionAlso written up in: pivik271/ctf-writeups
CorCTF Json
1 official solutionAlso written up in: juliancasaburi/CTFS-Writeups
Also written up in: google/google-ctf
Also written up in: pivik271/ctf-writeups
No(de)code
1 official solutionAlso written up in: cor.team
Shellcode
1 official solutionAlso written up in: rivit98/ctf-writeups
Sleeper Agent
1 official solutionAlso written up in: cor.team
Vmquackdis
1 official solutionAlso written up in: Pusty/writeups
Web8
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Also written up in: flowiri/CTF-Writeup, flowiri/CTF-Writeup
- dom-clobbering
- web
- react
Same technique in picoCTF: Live Art, secure-email-service, No FA
Index.7352e15a
2 official solutionsAlso written up in: strellic/my-ctf-challenges, flowiri/CTF-Writeup
- web
- quiz
- json
- post
Same technique in picoCTF: Live Art, secure-email-service, No FA
Also written up in: cor.team
- command
- injection
- blackbox
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Also written up in: strellic/my-ctf-challenges
Bootstrap.Min
1 official solutionAlso written up in: strellic/my-ctf-challenges
- deserialization
- web
- rust
Same technique in picoCTF: Live Art, secure-email-service, No FA
- nodejs
- express
- readfilesync
- web
Same technique in picoCTF: Live Art, secure-email-service, No FA
Reverse engineering6
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Also written up in: Surg-Dev/writeups
- elf
- msdos
- rev
- polyglot
Same technique in picoCTF: file-run2, Checkpass, WinAntiDbg0x100
Also written up in: rivit98/ctf-writeups
- obfuscation
- rev
- antidecompile
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Also written up in: rivit98/ctf-writeups
- jit
- rev
- vm
- rust
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- avx256
- rev
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- rev
- rockyou
- windows
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- llil
- riscv
- rev
- vm
- linalg
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Misc3
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Also written up in: strellic/my-ctf-challenges
- javascript
- sandbox
- misc
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
- solana
Same technique in picoCTF: PW Crack 2, Permissions, Specialer
Forensics1
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Also written up in: kiyotaka-akaiwa/ctf-writeups, IrfanNafiz/ctf-writeups, LeonGurin/My-CTF-Writeups, solocshaw/yet-another-ctf-writeups
- forensics
- wireshark
- drm
Same technique in picoCTF: FindAndOpen, Ph4nt0m 1ntrud3r, WebNet0